Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,291 results · page 131 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-34072 | Prior to version 2.2.0, an authentication bypass in middleware allows unauthenticated requests with an invalid session cookie to be treated as authenticated when the middleware’s session-validation fetch fails. | CRITICAL 9.8EPSS 0.44% | 1 April 2026 |
| CVE-2026-30643 | An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload. | CRITICAL 9.8EPSS 0.57% | 1 April 2026 |
| CVE-2026-20160 | A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. | CRITICAL 9.8EPSS 0.91% | 1 April 2026 |
| CVE-2026-20093 | A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. | CRITICAL 9.8EPSS 0.99% | 1 April 2026 |
| CVE-2024-43028 | A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request. | CRITICAL 9.8EPSS 1.53% | 1 April 2026 |
| CVE-2024-40489 | There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests. | CRITICAL 9.8EPSS 0.52% | 1 April 2026 |
| CVE-2026-31027 | TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. | CRITICAL 9.8EPSS 0.58% | 1 April 2026 |
| CVE-2026-29014 | MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. | CRITICAL 9.3EPSS 39.5% | 1 April 2026 |
| CVE-2026-4370 | A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. | CRITICAL 10.0EPSS 0.38% | 1 April 2026 |
| CVE-2025-15484 | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and… | CRITICAL 9.1EPSS 0.24% | 1 April 2026 |
| CVE-2026-5290 | Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.31% | 1 April 2026 |
| CVE-2026-5289 | Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.35% | 1 April 2026 |
| CVE-2026-5288 | Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.31% | 1 April 2026 |
| CVE-2025-71279 | An attacker may be able to compromise the security of Passkey-based authentication. | CRITICAL 9.3EPSS 0.45% | 1 April 2026 |
| CVE-2026-34449 | Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a… | CRITICAL 9.6EPSS 0.50% | 31 March 2026 |
| CVE-2026-34448 | Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -> Asset Field” enabled. | CRITICAL 9.0EPSS 0.49% | 31 March 2026 |
| CVE-2026-34406 | Prior to version 2.0.1, the edit_user endpoint (POST /api/auth/edituser/<pk>) allows Any user who can reach that endpoint and submit crafted permission to escalate their own account (or any other account) to superuser by including "is_superuser": true… | CRITICAL 9.4EPSS 0.51% | 31 March 2026 |
| CVE-2026-1579 | The MAVLink communication protocol does not require cryptographic authentication by default. | CRITICAL 9.3EPSS 0.93% | 31 March 2026 |
| CVE-2026-4800 | When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. | CRITICAL 9.8EPSS 2.76% | 31 March 2026 |
| CVE-2026-30285 | An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | CRITICAL 9.8EPSS 0.62% | 31 March 2026 |
| CVE-2026-3356 | The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. | CRITICAL 9.3EPSS 0.39% | 31 March 2026 |
| CVE-2026-30286 | An arbitrary file overwrite vulnerability in Funambol, Inc. | CRITICAL 9.8EPSS 0.64% | 31 March 2026 |
| CVE-2026-30283 | An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. | CRITICAL 9.8EPSS 0.51% | 31 March 2026 |
| CVE-2026-30282 | An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure. | CRITICAL 9.0EPSS 0.36% | 31 March 2026 |
| CVE-2026-30278 | An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | CRITICAL 9.8EPSS 0.53% | 31 March 2026 |
| CVE-2026-34361 | Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. | CRITICAL 9.3EPSS 0.30% | 31 March 2026 |
| CVE-2026-34359 | Because configured server URLs (e.g., http://tx.fhir.org) lack a trailing slash or host boundary check, an attacker-controlled domain like http://tx.fhir.org.attacker.com matches the prefix and receives Bearer tokens, Basic auth credentials, or API keys… | CRITICAL 9.1EPSS 0.16% | 31 March 2026 |
| CVE-2026-24164 | NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. | CRITICAL 9.8EPSS 0.47% | 31 March 2026 |
| CVE-2026-24148 | NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. | CRITICAL 9.4EPSS 0.35% | 31 March 2026 |
| CVE-2026-34243 | In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner. | CRITICAL 9.8EPSS 2.17% | 31 March 2026 |
| CVE-2026-34220 | Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL query fragments. | CRITICAL 9.3EPSS 0.43% | 31 March 2026 |
| CVE-2026-30281 | An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | CRITICAL 9.8EPSS 0.69% | 31 March 2026 |
| CVE-2026-30276 | An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | CRITICAL 9.8EPSS 0.67% | 31 March 2026 |
| CVE-2026-34532 | Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. | CRITICAL 9.1EPSS 0.28% | 31 March 2026 |
| CVE-2026-34202 | Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). | CRITICAL 9.2EPSS 0.73% | 31 March 2026 |
| CVE-2026-34162 | Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. | CRITICAL 10.0EPSS 0.42% | 31 March 2026 |
| CVE-2026-33579 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. | CRITICAL 9.4EPSS 0.83% | 31 March 2026 |
| CVE-2026-30314 | Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. | CRITICAL 9.8EPSS 1.20% | 31 March 2026 |
| CVE-2026-30312 | DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. | CRITICAL 9.8EPSS 1.66% | 31 March 2026 |
| CVE-2026-30311 | Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. | CRITICAL 9.8EPSS 1.66% | 31 March 2026 |
| CVE-2026-34156 | Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require allowlist (controlled by WORKFLOW_SCRIPT_MODULES env var). | EXPLOITCRITICAL 9.9EPSS 35.0% | 31 March 2026 |
| CVE-2026-30310 | In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands. | CRITICAL 9.8EPSS 0.51% | 31 March 2026 |
| CVE-2026-32917 | OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. | CRITICAL 9.2EPSS 1.97% | 31 March 2026 |
| CVE-2026-32916 | OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. | CRITICAL 9.2EPSS 0.46% | 31 March 2026 |
| CVE-2025-15618 | Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. | CRITICAL 9.1EPSS 0.33% | 31 March 2026 |
| CVE-2026-4317 | SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated attacker to execute arbitrary SQL commands in the database.Specifically, they could manipulate the value… | CRITICAL 9.3EPSS 0.34% | 31 March 2026 |
| CVE-2026-3107 | Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. | CRITICAL 9.3EPSS 0.13% | 31 March 2026 |
| CVE-2026-3106 | Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. | CRITICAL 9.3EPSS 0.15% | 31 March 2026 |
| CVE-2025-10559 | A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to read or write files in specific directories on the server. | CRITICAL 9.1EPSS 0.27% | 31 March 2026 |
| CVE-2026-32714 | Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python's str.format() to construct SQL queries with user-supplied data (such as issuer and key_id). | CRITICAL 9.8EPSS 0.49% | 31 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.